TACTIC: CREDENTIAL ACCESS
Keylogging (T1056.001): real cases
MITRE Definition ↗ Adversaries record keystrokes to harvest passwords and confidential communications.
Key Facts
Technique ID
T1056.001
Credential Access
Mapped Cases
2
Primary sources
Related Laws
0
Criminal statutes
- ATT&CK Technique Identifier: T1056.001.
- Tactical Phase: Credential Access.
- Substantiated in 2 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)
sentenced 2018-03-27
Primary Source Evidence Excerpt: Indictment ¶ 22, Page 12
"Carbanak malware contained keystroke logging modules to capture administrative credentials entered in terminal sessions."
U.S. District Court for the Western District of Washington
View full case dossier →
Target Corporation Point-of-Sale Data Breach (Fazio Mechanical Ingress)
settled 2014-04-02
Primary Source Evidence Excerpt: US-CERT Advisory TA14-002A
"Operatives deployed a customized variant of BlackPOS (Kaptoxa) malware across thousands of cash register POS terminals to scrape payment card magnetic stripe tracks from process memory."
U.S. District Court for the District of Minnesota
View full case dossier →